← Voltar à pesquisa de CVEs

CVE-2026-3646

LTL Freight Quotes

Descrição

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin-s webhook handler in all versions up to, and including, 3.3.13. This is due to missing authentication, authorization, and nonce verification on a standalone PHP file that directly processes GET parameters and updates WordPress options. This makes it possible for unauthenticated attackers to modify the plugin-s subscription plan settings, effectively downgrading the store from a paid plan to the Trial Plan, changing the store type, and manipulating subscription expiration dates, potentially disabling premium features such as Dropship and Hazardous Material handling.

CVSS 5.3EPSS 0.385%Risco 0.55
Ver fonte
Publicação
2026-04-08 05:16:06
Versões afetadas
<=3.3.13
Tipo
Installed app
Última alteração
2026-07-24 21:10:00
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N